Vulnerabilities > Mercedes Benz

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-47392 Unspecified vulnerability in Mercedes-Benz Mercedes ME
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
network
low complexity
mercedes-benz
5.3
2023-11-22 CVE-2023-47393 Unspecified vulnerability in Mercedes-Benz Mercedes ME
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive user information via unspecified vectors.
network
low complexity
mercedes-benz
5.3
2023-01-15 CVE-2023-23590 Unspecified vulnerability in Mercedes-Benz Xentry Retail Data Storage Firmware 7.8.1
Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request.
network
low complexity
mercedes-benz
7.5
2021-05-13 CVE-2021-23906 Improper Input Validation vulnerability in Mercedes-Benz User Experience
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
local
low complexity
mercedes-benz CWE-20
2.1
2021-05-13 CVE-2021-23907 Unspecified vulnerability in Mercedes-Benz Headunit Ntg6 Mercedes-Benz User Experience 2021
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
network
low complexity
mercedes-benz
7.5
2021-05-13 CVE-2021-23908 Type Confusion vulnerability in Mercedes-Benz Headunit Ntg6 Mercedes-Benz User Experience 2021
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
network
low complexity
mercedes-benz CWE-843
7.5
2021-05-13 CVE-2021-23909 Out-of-bounds Write vulnerability in Mercedes-Benz Hermes 2.1
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
network
low complexity
mercedes-benz CWE-787
7.5
2021-05-13 CVE-2021-23910 Out-of-bounds Write vulnerability in Mercedes-Benz Hermes 2.1
An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021.
network
low complexity
mercedes-benz CWE-787
7.5
2020-08-27 CVE-2020-16142 Use of Externally-Controlled Format String vulnerability in Mercedes-Benz Comand
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.
low complexity
mercedes-benz CWE-134
3.5
2018-10-09 CVE-2018-18071 Cleartext Transmission of Sensitive Information vulnerability in Mercedes-Benz Mercedes ME 2.11.0
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS.
network
low complexity
mercedes-benz CWE-319
5.0